8.4

CVSS3.0

CVE-2024-9880 - pandas: Command Injection in pandas-dev/pandas

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: March 26, 2025, 5:15 p.m.

6.5

CVSS3.0

CVE-2024-10481 - Cross-Site Request Forgery (CSRF) in comfyanonymous/comfyui

A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, when visited by authenticated ComfyUI users, can perform arbitrary API requests on behalf of the user. This can be exploited to perform actions such as u…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 12:50 p.m.

7.4

CVSS3.0

CVE-2024-7819 - CORS Misconfiguration in danswer-ai/danswer

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the applicat…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-11137 - IDOR Vulnerability in PATCH `/v1/runs/:id/score` Endpoint in lunary-ai/lunary

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the score data of any run by manipulating the id parameter in the request URL, which corresponds to the `runI…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

7.7

CVSS3.1

CVE-2024-7959 - SSRF in open-webui/open-webui

The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the…

πŸ“… Published: March 20, 2025, 10:09 a.m. πŸ”„ Last Modified: July 21, 2025, 8:06 p.m.

8.8

CVSS3.0

CVE-2024-11170 - Path Traversal in danny-avila/librechat

A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.

πŸ“… Published: March 20, 2025, 10:08 a.m. πŸ”„ Last Modified: July 15, 2025, 4:45 p.m.

4.3

CVSS3.0

CVE-2024-11821 - Privilege Escalation in langgenius/dify

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /consol…

πŸ“… Published: March 20, 2025, 10:08 a.m. πŸ”„ Last Modified: July 14, 2025, 5:25 p.m.

7.5

CVSS3.0

CVE-2024-12068 - Server-Side Request Forgery in haotian-liu/llava

A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such…

πŸ“… Published: March 20, 2025, 10:08 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:46 p.m.

6.5

CVSS3.0

CVE-2024-11037 - Path Traversal in binary-husky/gpt_academic

A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as the OpenAI API key. This vulnerability is exploitable on Windows operating syste…

πŸ“… Published: March 20, 2025, 10:08 a.m. πŸ”„ Last Modified: July 31, 2025, 2:51 p.m.

7.5

CVSS3.0

CVE-2024-8763 - Regular Expression Denial of Service (ReDoS) in lunary-ai/lunary

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in the compileTextTemplate function. The affected version is git be54057. An attacker can exploit this vulnerability by manipulating the regular expression /{{(.*?)}}/g, causing the …

πŸ“… Published: March 20, 2025, 10:08 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 6294 of 34,919
Β« previous page Β» next page
Filters